mcp-server-git
A Model Context Protocol server providing tools to read, search, and manipulate Git repositories programmatically via LLMs
Findings (8)
- MED
VULN_KNOWN— GHSA-5cgr-j3jf-jw3v: mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations. See https://osv.dev/vulnerability/GHSA-5cgr-j3jf-jw3v - MED
VULN_KNOWN— GHSA-9xwc-hfwc-8w59: mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files. See https://osv.dev/vulnerability/GHSA-9xwc-hfwc-8w59 - MED
VULN_KNOWN— GHSA-j22h-9j4x-23w5: mcp-server-git has missing path validation when using --repository flag. See https://osv.dev/vulnerability/GHSA-j22h-9j4x-23w5 - MED
VULN_KNOWN— GHSA-vjqx-cfc4-9h6v: mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries. See https://osv.dev/vulnerability/GHSA-vjqx-cfc4-9h6v - LOW
VULN_KNOWN— PYSEC-2026-1621: mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations. See https://osv.dev/vulnerability/PYSEC-2026-1621 - LOW
VULN_KNOWN— PYSEC-2026-1622: mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files. See https://osv.dev/vulnerability/PYSEC-2026-1622 - LOW
VULN_KNOWN— PYSEC-2026-1623: mcp-server-git has missing path validation when using --repository flag. See https://osv.dev/vulnerability/PYSEC-2026-1623 - LOW
VULN_KNOWN— PYSEC-2026-2630: mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries. See https://osv.dev/vulnerability/PYSEC-2026-2630
Embed this badge
[](https://vulnrable.com/mcp/mcp-server-git/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.